Berlin State Network: What Lay Between All-Clear and Leak

On 19 August Berlin reported that nothing sensitive had leaked. On 4 September the data set was online. What lies in between – and what follows from it.

On Friday, 14 August 2026, the State of Berlin disconnected two Senate administrations from the state network – the one for urban development, building and housing, and the one for mobility, transport, climate protection and the environment. The compromise had come to light during forensic investigations. Both were reachable only by telephone afterwards; housing benefit could neither be applied for nor paid out. The state criminal police office, the public prosecutor and the BSI were brought in.

Five days later, Governing Mayor Kai Wegner said that according to current findings no sensitive data had left the network – and qualified it in the same breath: “That is the present state of knowledge.”

On 4 September the perpetrators, the Rhysida group, published the data set – around 5.26 terabytes according to an analysis of what was actually released.

Between those two statements lies the real lesson of this incident – and it has nothing to do with Berlin, but with how attacks of this kind unfold.

What actually happened

On 7 August the Senate Department for Mobility reported a first outflow – seven days before it was cut off from the state network. Forensic work then found further outflows and dates the window to 7 to 12 August. The exfiltration therefore did not end when it was discovered: it continued while the investigation was already running.

On 28 August Berlin made public that it would not pay. After a special session of the Senate, Wegner stated that the State of Berlin was being blackmailed and that it would not engage with the extortion attempt. The group set a deadline and offered the data with a minimum bid of 30 bitcoin – around two million euros.

On 4 September the publication followed. The attackers claim 5.79 terabytes and roughly 1.44 million files with personal details on 12,076 individuals – figures from the leak entry, not confirmed by Berlin. An analysis of what was actually released arrives at 5.26 terabytes with a practically identical file count: the attackers overstated the volume, not the number of documents. The analysis classifies the material as personnel, financial and administrative records plus access credentials.

One detail of that analysis deserves particular attention: it also finds contents of the recycle bin and temporarily saved Word and Excel files among the published material. Anyone who mentally equates leaked data with the curated document store underestimates the damage. What is taken is what is reachable – including what an organisation believed it had deleted.

Why the early all-clear was not a failure

It would be cheap to hold the statement of 19 August against the state. It was carefully worded, Wegner limited it himself – and it describes exactly the position every organisation is in during the first days: you see what your own systems logged, not what the other side already holds.

That is precisely the point for your organisation. In the first days after a finding there is no reliable statement about whether data has left. There is only the statement that so far no outflow could be seen. Anyone who turns that into an internal all-clear – towards management, the works council, customers – may have to withdraw it weeks later, and then in a situation where nobody is listening calmly any more.

The practical consequence is uncomfortable but simple: word your interim statements so that they still hold if it turns out worse.

How they got in is publicly unresolved

On the question of how the attackers technically got in, there is no conclusive public answer weeks after the incident.

A side note on that, because otherwise somebody else will draw the connection: in a warning dated 4 September, the BSI describes a concrete chain for the compromise of an unnamed state institution in August 2026 – a prepared website, a faked CAPTCHA, a PowerShell command executed by the user themselves, then sideloading and a back channel over port 443 – and attributes the malware used to the same group behind Rhysida. Whether that was the route into Berlin, the document does not say. And no other public source says so either.

For your own planning this is the most important observation of the entire affair. If a federal state with the state criminal police office, the public prosecutor and the BSI behind it does not publicly name the initial access after weeks, you should not expect to know it for your own organisation within three days. An emergency plan that assumes you know the route before you act is not a plan.

What the disconnection shows

The first measure in Berlin was structural: two administrations were separated from the state network – not the rest. That such a separation is available as an option at all is not self-evident but a question of network architecture. It is not cheap either: specialist procedures ran on the disconnected sites, and housing benefit stood still. Containment costs – the only question is whether it is an option at all.

In a flat network that option does not exist. There, containment means everything off, or nothing off. Segmentation is therefore not a compliance exercise but the precondition for having a choice at all in an emergency.

For your organisation the same applies to recovery. Backups reachable and alterable from the same network are not backups in a ransomware case. Immutable, separated, and – the part almost everyone skips – restored at least once before it matters.

What that means for the deadline

In its warning the BSI relays the knowledge of a commercial service provider: being named on this group’s leak site is followed by actual publication in 92 percent of cases, on average 11 days later. Berlin confirms the first part – and undercut the second: seven days lay between the listing on 28 August and the publication on 4 September.

A good week is not negotiating time. It is the time to identify those affected, meet reporting obligations and prepare communication that is not improvised on the day of publication. And the average is no promise – Berlin had four days less. Whoever starts organising that week only after the finding loses it to the organising.

How sector7 supports you

What carries over to your organisation comes to us from two directions. From the defence industry: our engineers hold VS-NfD briefings and have project experience in classified environments of the defence sector – from the architecture and piloting of an SD-WAN landscape for a group in that sector to taking an application delivery platform into regular operation. And from the work for municipalities and public authorities. What carries over is less the technology than the way it is handled: documented changes, traceable access, no shortcuts.

In practice that means three things. We plan and operate segmented networks with controlled transitions – so that containment is an option and not a total outage. We set up immutable backups on geo-redundant targets of our own, test the restore and rehearse the emergency plan instead of filing it. And we run our systems on our own infrastructure in Germany, with our own server park and our own IP address space.

One limit we name up front, because otherwise it comes up too late in the conversation: VS-NfD is the lowest German classification level and the only one that works without a formal security clearance. We hold VS-NfD briefings – we are not a company under official secret-protection supervision. Where your contract demands more, we say so beforehand. More on that under defence industry and defence suppliers.

Sources

Let's talk about your situation.